2 * Copyright (c) 2004 - 2007 Kungliga Tekniska Högskolan
3 * (Royal Institute of Technology, Stockholm, Sweden).
6 * Redistribution and use in source and binary forms, with or without
7 * modification, are permitted provided that the following conditions
10 * 1. Redistributions of source code must retain the above copyright
11 * notice, this list of conditions and the following disclaimer.
13 * 2. Redistributions in binary form must reproduce the above copyright
14 * notice, this list of conditions and the following disclaimer in the
15 * documentation and/or other materials provided with the distribution.
17 * 3. Neither the name of the Institute nor the names of its contributors
18 * may be used to endorse or promote products derived from this software
19 * without specific prior written permission.
21 * THIS SOFTWARE IS PROVIDED BY THE INSTITUTE AND CONTRIBUTORS ``AS IS'' AND
22 * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
23 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
24 * ARE DISCLAIMED. IN NO EVENT SHALL THE INSTITUTE OR CONTRIBUTORS BE LIABLE
25 * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
26 * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
27 * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
28 * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
29 * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
30 * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
35 __RCSID("$Heimdal: collector.c 20778 2007-06-01 22:04:13Z lha $"
39 AlgorithmIdentifier alg
;
40 hx509_private_key private_key
;
41 heim_octet_string localKeyId
;
44 struct hx509_collector
{
46 hx509_certs unenvelop_certs
;
49 struct private_key
**data
;
56 _hx509_collector_alloc(hx509_context context
, hx509_lock lock
, struct hx509_collector
**collector
)
58 struct hx509_collector
*c
;
63 c
= calloc(1, sizeof(*c
));
65 hx509_set_error_string(context
, 0, ENOMEM
, "out of memory");
70 ret
= hx509_certs_init(context
, "MEMORY:collector-unenvelop-cert",
71 0,NULL
, &c
->unenvelop_certs
);
78 ret
= hx509_certs_init(context
, "MEMORY:collector-tmp-store",
81 hx509_certs_free(&c
->unenvelop_certs
);
91 _hx509_collector_get_lock(struct hx509_collector
*c
)
98 _hx509_collector_certs_add(hx509_context context
,
99 struct hx509_collector
*c
,
102 return hx509_certs_add(context
, c
->certs
, cert
);
106 free_private_key(struct private_key
*key
)
108 free_AlgorithmIdentifier(&key
->alg
);
109 if (key
->private_key
)
110 _hx509_private_key_free(&key
->private_key
);
111 der_free_octet_string(&key
->localKeyId
);
116 _hx509_collector_private_key_add(hx509_context context
,
117 struct hx509_collector
*c
,
118 const AlgorithmIdentifier
*alg
,
119 hx509_private_key private_key
,
120 const heim_octet_string
*key_data
,
121 const heim_octet_string
*localKeyId
)
123 struct private_key
*key
;
127 key
= calloc(1, sizeof(*key
));
131 d
= realloc(c
->val
.data
, (c
->val
.len
+ 1) * sizeof(c
->val
.data
[0]));
134 hx509_set_error_string(context
, 0, ENOMEM
, "Out of memory");
139 ret
= copy_AlgorithmIdentifier(alg
, &key
->alg
);
141 hx509_set_error_string(context
, 0, ret
, "Failed to copy "
142 "AlgorithmIdentifier");
146 key
->private_key
= private_key
;
148 ret
= _hx509_parse_private_key(context
, &alg
->algorithm
,
149 key_data
->data
, key_data
->length
,
155 ret
= der_copy_octet_string(localKeyId
, &key
->localKeyId
);
157 hx509_set_error_string(context
, 0, ret
,
158 "Failed to copy localKeyId");
162 memset(&key
->localKeyId
, 0, sizeof(key
->localKeyId
));
164 c
->val
.data
[c
->val
.len
] = key
;
169 free_private_key(key
);
175 match_localkeyid(hx509_context context
,
176 struct private_key
*value
,
183 if (value
->localKeyId
.length
== 0) {
184 hx509_set_error_string(context
, 0, HX509_LOCAL_ATTRIBUTE_MISSING
,
185 "No local key attribute on private key");
186 return HX509_LOCAL_ATTRIBUTE_MISSING
;
189 _hx509_query_clear(&q
);
190 q
.match
|= HX509_QUERY_MATCH_LOCAL_KEY_ID
;
192 q
.local_key_id
= &value
->localKeyId
;
194 ret
= hx509_certs_find(context
, certs
, &q
, &cert
);
197 if (value
->private_key
)
198 _hx509_cert_assign_key(cert
, value
->private_key
);
199 hx509_cert_free(cert
);
205 match_keys(hx509_context context
, struct private_key
*value
, hx509_certs certs
)
209 int ret
, found
= HX509_CERT_NOT_FOUND
;
211 if (value
->private_key
== NULL
) {
212 hx509_set_error_string(context
, 0, HX509_PRIVATE_KEY_MISSING
,
213 "No private key to compare with");
214 return HX509_PRIVATE_KEY_MISSING
;
217 ret
= hx509_certs_start_seq(context
, certs
, &cursor
);
223 ret
= hx509_certs_next_cert(context
, certs
, cursor
, &c
);
228 if (_hx509_cert_private_key(c
)) {
233 ret
= _hx509_match_keys(c
, value
->private_key
);
235 _hx509_cert_assign_key(c
, value
->private_key
);
243 hx509_certs_end_seq(context
, certs
, cursor
);
246 hx509_clear_error_string(context
);
252 _hx509_collector_collect_certs(hx509_context context
,
253 struct hx509_collector
*c
,
254 hx509_certs
*ret_certs
)
261 ret
= hx509_certs_init(context
, "MEMORY:collector-store", 0, NULL
, &certs
);
265 ret
= hx509_certs_merge(context
, certs
, c
->certs
);
267 hx509_certs_free(&certs
);
271 for (i
= 0; i
< c
->val
.len
; i
++) {
272 ret
= match_localkeyid(context
, c
->val
.data
[i
], certs
);
275 ret
= match_keys(context
, c
->val
.data
[i
], certs
);
286 _hx509_collector_collect_private_keys(hx509_context context
,
287 struct hx509_collector
*c
,
288 hx509_private_key
**keys
)
294 for (i
= 0, nkeys
= 0; i
< c
->val
.len
; i
++)
295 if (c
->val
.data
[i
]->private_key
)
298 *keys
= calloc(nkeys
+ 1, sizeof(**keys
));
300 hx509_set_error_string(context
, 0, ENOMEM
, "malloc - out of memory");
304 for (i
= 0, nkeys
= 0; i
< c
->val
.len
; i
++) {
305 if (c
->val
.data
[i
]->private_key
) {
306 (*keys
)[nkeys
++] = c
->val
.data
[i
]->private_key
;
307 c
->val
.data
[i
]->private_key
= NULL
;
310 (*keys
)[nkeys
++] = NULL
;
317 _hx509_collector_free(struct hx509_collector
*c
)
321 if (c
->unenvelop_certs
)
322 hx509_certs_free(&c
->unenvelop_certs
);
324 hx509_certs_free(&c
->certs
);
325 for (i
= 0; i
< c
->val
.len
; i
++)
326 free_private_key(c
->val
.data
[i
]);